CVE-2025-2172: Aviatrix Controller
Medium severity, CVSS 6.6. EPSS: 12.2% chance of exploitation in the next 30 days.
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
Affected products
- Aviatrix Controller
Published 2025-06-23. Last modified 2026-06-17.